QID 590544

Date Published: 2021-10-07

QID 590544: Schneider Electric EcoStruxure and SCADAPack Path Traversal Vulnerability (ICSA-21-259-02)

AFFECTED PRODUCTS
The following products and versions are affected:
EcoStruxure Control Expert: All versions, including former Unity Pro
EcoStruxure Process Expert: All versions, including former HDCS
SCADAPack RemoteConnect for x70: All versions

QID Detection Logic (Authenticated)
QID checks for the Vulnerable version using windows registry keys

Successful exploitation of this vulnerability could result in code execution on the engineering workstation.

  • CVSS V2 rated as High - 7.5 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-21-259-02 for affected packages and patching details.

    Vendor References

    CVEs related to QID 590544

    Software Advisories
    Advisory ID Software Component Link
    ICSA-21-259-02 URL Logo www.us-cert.gov/ics/advisories/ICSA-21-259-02